# CVE-2026-89569

## Summary

- **CVE ID:** CVE-2026-89569
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: serialize security confirmation handling

rfcomm_security_cfm() looks up a session on session_list and then walks
its DLC list without holding rfcomm_mutex. Since RFCOMM session teardown
uses rfcomm_mutex, krfcommd can close and free the same session and DLCs
concurrently:

  hci_rx_work                    krfcommd
  -----------                    ---------
  rfcomm_session_get()
                                 rfcomm_lock()
                                 rfcomm_session_close()
                                   rfcomm_dlc_unlink()
                                   rfcomm_session_del()
                                     kfree(s)
                                 rfcomm_unlock()
  walk s->dlcs

The callback can then read a freed session list head and touch freed DLCs
while updating their flags or timers.

Serialize the session lookup and DLC traversal in rfcomm_security_cfm()
with rfcomm_mutex. This matches the existing RFCOMM session lifetime
rules and prevents concurrent rfcomm_session_del() / rfcomm_dlc_unlink()
from tearing the objects down while the callback is using them.

KASAN reported:

  BUG: KASAN: slab-use-after-free in rfcomm_security_cfm+0x41c/0x440
  Read of size 8 at addr ffff888111fb3960 by task kworker/u17:1/89
  Workqueue: hci0 hci_rx_work
  Call Trace:
   rfcomm_security_cfm+0x41c/0x440
   hci_encrypt_cfm+0x139/0x590
   hci_encrypt_change_evt+0x37b/0xc40
   hci_event_packet+0x71b/0xb20
   hci_rx_work+0x293/0x730
  Allocated by task 69:
   rfcomm_session_add+0x9e/0x2f0
   rfcomm_run+0x44b/0x41e0
  Freed by task 69:
   kfree+0x131/0x3c0
   rfcomm_session_del+0x188/0x220
   rfcomm_run+0x1985/0x41e0

## Affected Products

- Linux — Linux (08c30aca9e698faddebd34f81e1196295f9dc063)
- Linux — Linux (3.10)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/1b7841ffad08e911e8c4b9470f3fa08423568940)
- [CNA](https://git.kernel.org/stable/c/946d76db77ee5f922968ce558629ae47b381e3fc)
- [CNA](https://git.kernel.org/stable/c/fbf7961964a6e93360179f64712320ae9a1e9577)
- [CNA](https://git.kernel.org/stable/c/759c185d0bbdb131357408f50b8735e04ed3caff)
- [CNA](https://git.kernel.org/stable/c/62ce8b33eb238cf18c15207332fbdc26d858f592)
- [CNA](https://git.kernel.org/stable/c/3873f3449701b3dc98cba577923be6493598e7a1)
- [CNA](https://git.kernel.org/stable/c/7ded3264106418c6456ccceaafd9fda596ce12c3)
- [CNA](https://git.kernel.org/stable/c/82425b14f0fb22e46cfddc56d6465570f5ed0ce6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 27.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._